Trilegal
Website:
trilegal.com
Job details:
Information Security Manager
Experience: 15–16 Years
Location: Bengaluru, India
Function: Information Security
Industry Preference: Legal Services / Professional Services / Consulting
The Information Security Manager will operate within the Information Security function and will be responsible for driving the execution, governance, and reporting of key cybersecurity initiatives across the firm. The role will ensure that security programs aligned to Risk Management, Business Continuity, Disaster Recovery, GRC, and Cloud Security are executed effectively and tracked through a structured governance framework.
The individual will act as a central coordination point between Information Security, Technology, Risk, Compliance, and business stakeholders, ensuring that cybersecurity initiatives are delivered on time, within scope, and aligned with regulatory and client expectations.
Key Responsibilities
1. Security Program Governance
Establish and manage the Information Security governance framework.
Track and report progress of security initiatives, remediation programs, and regulatory projects.
Maintain program dashboards, risk registers, and executive reporting for the leadership team.
Conduct monthly governance reviews with security leadership and the DIG office.
2. Risk & Compliance Program Management
Coordinate enterprise risk assessments and security risk remediation programs.
Track closure of audit observations, risk findings, and compliance gaps.
Work closely with the GRC team on policy implementation and regulatory compliance initiatives.
3. Business Continuity & Disaster Recovery Programs
Manage the BCP/DR program lifecycle, including:
Business Impact Analysis (BIA)
Risk assessments
DR testing exercises
Tabletop simulations
Track action items arising from BCP/DR drills and resilience programs.
4. Cloud Security Initiatives
Coordinate security initiatives across cloud platforms, including AWS, Azure, and GCP.
Track implementation of cloud security controls, architecture reviews, and remediation programs.
Work with cloud engineering teams to ensure security alignment.
5. Stakeholder Management
Act as a bridge between the CISO office, IT teams, business functions, and external vendors.
Manage cross-functional dependencies for security initiatives.
Provide executive-level reporting and program updates to leadership committees.
6. Metrics & Reporting
Develop security KPIs and program maturity dashboards.
Maintain the security roadmap and transformation tracking.
Produce quarterly board-level reports on cybersecurity initiatives.
Required Skills & Experience
Experience
15–16 years of total experience, with at least 8–10 years in PMO, program management, or information security management roles.
Experience managing enterprise cybersecurity or technology transformation programs.
Domain Knowledge
Strong understanding of:
- Information Security Governance
- Enterprise Risk Assessment
- Business Continuity & Disaster Recovery
- GRC frameworks
- Cloud security fundamentals
Familiarity with standards such as:
- ISO 27001
- NIST
- SOC 2
- Regulatory compliance frameworks
Preferred Certifications
One or more of the following preferred:
- PMP / PRINCE2
- CISA
- CRISC
- CISM
- ISO 27001 Lead Implementer / Lead Auditor
Key Competencies
- Strong information security program management and governance experience
- Ability to manage multiple concurrent cybersecurity initiatives
- Strong executive communication and reporting skills
- Risk-oriented thinking
- Strong stakeholder management, influence, and coordination skills
Success Metrics for the Role
- Timely delivery of security roadmap initiatives
- Closure rate of security risk remediation programs
- Effective BCP/DR program execution
- Quality and effectiveness of Information Security reporting and governance dashboards
We are an equal opportunity employer and value diversity. We do not discriminate based on gender, race, age, sexual orientation, and religious identities or any other applicable characteristics protected by law. We seek individuals who uphold the highest standards of integrity, demonstrate professionalism in every interaction, treat others with respect, and consistently align personal ambition with the collective goals of the firm.
The incumbent is required to comply with the Firm’s Information Security policies and procedures, including safeguarding confidential information, adhering to secure data handling practices, and promptly reporting information security incidents.
Click on Apply to know more.